Hi,
Splunk logs are truncated to 10,000 characters.
Please let me know TRUNCATE=20,000 need to change in Splunk installed location or forwarder installation location .
Regards,
Madhusri R
Hi @Madhusri,
TRUNCATE is an option of props.conf (for more infos see at https://docs.splunk.com/Documentation/Splunk/8.2.2/Admin/Propsconf)
so you have to put it in your Indexers and (if present) Heavy Forwarders.
Ciao.
Giuseppe
Hi @Madhusri,
you could put props.conf in $SPLUNK_HOME/system/local, but I don't like it.
I hint to create a custom dedicated Technical Add-On (TA), called e.g. TA_Indexers, containing your props.conf and eventual other conf files.
The TA will be located in $SPLUNK_HOME/apps
Ciao.
Giuseppe